Vulnerability index

Browse CVEs

4,337 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 10.0 CVE-2025-63216 The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse… Idgateway Firmware Mitigation only Fix from $2,3002025-11-18 HIGH 7.5 CVE-2024-21635 Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. When a user changes their passw… Memos after 0.18.1 Fix from $1,9502025-11-14 CRITICAL 9.8 CVE-2025-64717 ZITADEL is an open source identity management platform. Starting in version 2.50.0 and prior to versions 2.71.19, 3.4.4, and 4.6.6, a vulnerability i… Zitadel 2.71.19 / 3.4.4+ Fix from $2,3002025-11-13 HIGH 8.2 CVE-2025-12998 Improper Authentication vulnerability in TYPO3 Extension "Modules" codingms/modules.This issue affects Extension "Modules": before 4.3.11, from 5.0.0… Mitigation only Fix from $1,9502025-11-12 CRITICAL 9.3 CVE-2025-64513 Milvus is an open-source vector database built for generative AI applications. An unauthenticated attacker can exploit a vulnerability in versions pr… Patch available Fix from $2,3002025-11-10 MEDIUM 6.3 CVE-2025-64434 KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, due to the peer verification logic in virt-handler (via ver… Kubevirt 1.5.3+ Fix from $1,6002025-11-07 CRITICAL 9.3 CVE-2025-3222 Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows Authentication Abuse.This issue affects Smallworld: 5.3.3 and… Mitigation only Fix from $2,3002025-11-07 MEDIUM 6.7 CVE-2025-20730 In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege if a mal… Yocto Mitigation only Fix from $1,6002025-11-04 CRITICAL 9.8 CVE-2025-64103 Starting from 2.53.6, 2.54.3, and 2.55.0, Zitadel only required multi factor authentication in case the login policy has either enabled requireMFA or… Zitadel 2.71.18 / 3.4.3+ Fix from $2,3002025-10-29 HIGH 7.6 CVE-2025-60424 A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a brut… Fusion Mitigation only Fix from $1,9502025-10-27 CRITICAL 9.1 CVE-2025-62717 Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing lo… Emlog Patch available Fix from $2,3002025-10-24 CRITICAL 9.8 CVE-2025-43995 Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with… Storage Manager 2020+ Fix from $2,3002025-10-24 HIGH 8.8 CVE-2025-6979 Captive Portal can allow authentication bypass No fix yet Fix from $1,9502025-10-23 HIGH 8.1 CVE-2025-62169 OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of the testing branch and versions… Patch available Fix from $1,9502025-10-23 MEDIUM 5.4 CVE-2025-62398 A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially co… Moodle 4.4.11 / 4.5.7+ Fix from $1,6002025-10-23 CRITICAL 9.8 CVE-2025-56447 TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure. Mitigation only Fix from $2,3002025-10-22 CRITICAL 9.8 CVE-2025-41108 The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an attacker to send commands to the robot from an external att… Vision 60 Firmware Mitigation only Fix from $2,3002025-10-22 HIGH 8.8 CVE-2025-41110 Encrypted WiFi and SSH credentials were found in the Ghost Robotics Vision 60 v0.27.2 APK. This vulnerability allows an attacker to connect to the ro… Vision 60 Firmware Mitigation only Fix from $1,9502025-10-22 CRITICAL 9.8 CVE-2025-60772 Improper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017, allows a remote unauthenticated attacker to escalate … Mitigation only Fix from $2,3002025-10-21 CRITICAL 9.8 CVE-2025-11625 Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypass and leaking of clients cre… Wolfssh after 1.4.20 Fix from $2,3002025-10-21 CRITICAL 9.8 CVE-2025-11942 A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the component Pairing. Executing manipulation can lead to miss… X200 Firmware after 2025-10-10 Fix from $2,3002025-10-19 MEDIUM 5.3 CVE-2025-11852 A vulnerability was found in Apeman ID71 218.53.203.117. The impacted element is an unknown function of the file /onvif/device_service of the compone… Mitigation only Fix from $1,6002025-10-16 CRITICAL 9.1 CVE-2025-61922 PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5… Prestashop Checkout 7.4.4.1 / 7.5.0.5+ Fix from $2,3002025-10-16 HIGH 7.8 CVE-2025-43281 The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be able to elevate their privil… macOS 15.6+ Fix from $1,9502025-10-15 HIGH 8.8 CVE-2025-10293 The Keyy Two Factor Authentication (like Clef) plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,… Mitigation only Fix from $1,9502025-10-15 CRITICAL 9.5 CVE-2025-62376 pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit 467db0b9ea0d9a929dc89b41f6eb59f7cfc68bef, the /workspace endpoi… Patch available Fix from $2,3002025-10-14 HIGH 7.0 CVE-2025-55340 Improper authentication in Windows Remote Desktop Protocol allows an authorized attacker to bypass a security feature locally. Windows 10 21h2 10.0.19044.6456 / 10.0.19045.6456+ Fix from $1,9502025-10-14 MEDIUM 6.5 CVE-2025-53845 An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenticated a… Fortianalyzer 7.4.7 / 7.6.4+ Fix from $1,6002025-10-14 CRITICAL 9.8 CVE-2025-9063 An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exploitation of this vulnerabili… Factorytalk View after 15.0 Fix from $2,3002025-10-14 CRITICAL 9.1 CVE-2025-9064 A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device … Factorytalk View after 15.0 Fix from $2,3002025-10-14